AI Weekly Malaysia

Back to items Summaries

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

ID
27172
Status
summarized
Published
22 Sep 2026, 3:52 PM
Fetched
22 Sep 2026, 6:12 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.0
Created
22 Sep 2026, 6:13 PM
Tags
Audience
developers

What happened

Trellix researchers report that the SideCopy APT group (active since 2019, linked to Pakistan) has expanded spear-phishing targeting from Indian government/defense to academic institutions, using weaponized ZIP archives containing LNK files disguised as PDFs to deliver a multi-stage payload via mshta.exe and reflective DLL loading. The attack chain includes anti-forensic self-deletion and persistence via Windows Registry Run Keys.

Why it matters

This is a geopolitically targeted espionage campaign with no direct impact on Malaysian builders or their tooling. The technical details (LNK spoofing, HTA abuse, reflective DLL loading) are standard APT tradecraft worth noting only if you work in threat intelligence or secure academic/government networks in the region.

Discussion angle

Brief mention only: how LNK-file spoofing and mshta.exe abuse remain reliable initial-access techniques, and whether any audience members supporting academic or government clients in SEA should be flagging similar lures.

Top